Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 179

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
One year on from the UK's grand AI plan: Has its infrastructure buildout been a success?
How to find the log in page in q2amarket.com
The 'Trump-class' battleship faces a large obstacle in its way: Reality
Virginia offshore wind developer sues over Trump administration order halting projects
New NASA boss Isaacman says U.S. will return to the moon within Trump's term
S&P 500 closes little changed after touching fresh record, posts winning week: Live updates
Are dividends better for investors than stock buybacks? It all depends
Morgan Stanley says these are top stock picks in 2026, including Nvidia
Putin says Russia will achieve its Ukraine aims by force if Kyiv doesn't want peace
Forget Gen Z and Millennials — the over-50s ‘Silver Spenders’ are powering investment opportunities, including these stocks